Trust and governance
Outsourcing should not mean losing control. Before work begins we define who decides, who approves, who has access, how information is protected, how issues escalate, and how the relationship exits cleanly.
Clear lines, named people
The two most common outsourcing failures are work requested informally that nobody has costed, and problems that escalate too late to fix. Both are prevented by knowing who talks to whom.
Named roles on both sides
Each party appoints an Executive Sponsor and Engagement Manager. We deliver through a Service Delivery Lead; you route instructions and escalation through your Engagement Owner.
A governance rhythm
Service reviews, monthly business reviews and quarterly steering meetings — sized to the engagement.
A decision trail
A maintained log of issues, risks, actions and decisions, so what was agreed and why is determinable afterwards rather than debatable.
Controls that travel with your data
We comply with the Data Privacy Act of 2012, its implementing rules and applicable National Privacy Commission issuances. For personal data processed on your instructions you are the Personal Information Controller and we are the Personal Information Processor.
Role-based access
Granted by role, reviewed on a cycle.
Least privilege
The minimum access the work requires, and no more.
Segregation of duties
Preparation, review and approval held by different people.
Documented approvals
Material actions carry a recorded, traceable authorisation.
Confidentiality
Survives termination — indefinitely for trade secrets and personal data.
Exception reporting
Material exceptions, suspected fraud and security incidents are escalated.
Data-subject support
Access requests, impact assessments and breach response supported.
Clean exit
Data returned or deleted on exit, subject to legal retention.
Where our work ends
Our corporate purpose covers business support, management consulting and operational assistance. It excludes activities constituting the practice of professions regulated by the PRC, the IBP or other regulatory bodies — a working boundary, not a footnote.
The standard boundary, applied to every engagement
ProsInMotion performs
- Administrative, operational and processing work
- Preparation, coordination and documentation
- Compliance tracking, filing support and reporting
- Service management against agreed levels
You retain
- Governance, management and business decisions
- Accounting policies, estimates and tax positions
- Approval of filings and external representations
- Control of funds, seals and government credentials
A licensed professional is required for
- Statutory audit and any assurance opinion
- Legal advice, opinions and representation as counsel
- Tax opinions and contested assessments
- Notarisation and regulated certifications
Where a licensed professional is required, that person is engaged separately, by you, under their own engagement and their own fee. We identify the need and coordinate — we do not perform the work and do not invoice for it.
A genuine managed service, not labour supply
- Our personnel remain our employees, contractors or authorised representatives — not yours
- We exercise employer prerogatives: supervision, work allocation, performance, leave, discipline and substitution
- We carry the wages, statutory benefits, contributions and employment records
- You specify outcomes, policies, priorities, controls and acceptance criteria
- Service concerns are raised with our designated manager, not with the individual
Engagements are built around outputs, methods and service levels — not the recruitment or supply of workers. DOLE Department Circular No. 01-17 recognises that genuine business-process and back-office outsourcing is not contemplated by Department Order No. 174 where an entire or specific business process is involved.
You should be able to leave
An engagement that cannot be unwound cleanly is a trap, not a service. Knowledge transfer, data return and exit planning are built in from the start.
- An agreed exit plan with knowledge transfer
- Return or transfer of your data and property
- Access revoked and records preserved as legally required
- Notice periods and any transition charges stated before you sign
Lines we will not cross
Both parties comply with applicable anti-bribery, anti-fraud, sanctions and anti-money-laundering requirements. We may refuse or stop an instruction that appears unlawful, misleading, unethical or unsafe.
- Falsifying records, bypassing controls or concealing incidents
- Backdating documents
- Improper payments, kickbacks or undisclosed commissions
- Submitting anything inaccurate, misleading or inconsistent with official records
We may serve competitors, provided confidentiality is protected and conflicts managed. No exclusivity exists unless stated in a Service Order.
Frameworks we design against
ISO 9001:2015
Quality management
ISO/IEC 27001:2022
Information security
ISO 22301:2019
Business continuity
ISO 37301:2021
Compliance management
ISO 10002:2018
Complaints handling
ITIL 4 · COBIT · COSO
Service management, IT governance, internal control
Questions about how we would handle your data or your risk?
Ask them before you sign, not after. We are happy to walk your legal, compliance or IT team through the control environment and the data-processing schedule in detail.